CVE-2023-27224
CRITICALNginx Proxy Manager 2.9.19 - Code Execution via Lua in Configuration File
Title source: manualDescription
An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file.
References (2)
Core 2
Core References
Scores
CVSS v3
9.8
EPSS
0.0122
EPSS Percentile
64.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-77
Status
published
Products (1)
jc21/nginx_proxy_manager
2.9.19
Published
Mar 22, 2023
Tracked Since
Feb 18, 2026